ecapture is a free, open source threat detection & response project written in C and released under Apache-2.0. It has 15,490 GitHub stars, 1,647 forks and 4 open issues, and was last pushed 7 hours ago. On this registry it ranks #6 of 58 tracked projects in Threat Detection & Response, with 5 head-to-head comparisons available.

What is ecapture?

eCapture (旁观者) is an open-source eBPF tool that captures SSL/TLS plaintext, database queries, and shell history on Linux and Android for security auditors, network engineers, and self-hosters who need visibility into encrypted traffic without intercepting it.

What it is

eCapture is a C and Go program that uses eBPF probes — including uprobe and tc-based hooks — to read plaintext out of TLS/SSL libraries as a running process encrypts or decrypts it, rather than sitting between the client and the server. It runs on Linux and Android, on x86_64 (kernel 4.18 or newer) and aarch64 (kernel 5.5 or newer), and requires root privileges or specific Linux capabilities as described in the project's docs/minimum-privileges.md. It is distributed under the Apache-2.0 licence.

The problem it solves is that inspecting HTTPS normally forces a choice between installing a custom CA certificate on every target and terminating connections in a man-in-the-middle proxy — an intrusive, often impossible step on managed or mobile devices. eCapture replaces that MITM proxy and custom CA setup entirely: it searches the default library paths from /etc/ld.so.conf to locate the system's OpenSSL and captures traffic as it happens, so nothing about the target application's configuration has to change.

Key capabilities

  • The tls module captures plaintext TLS/SSL traffic without a CA certificate, supporting OpenSSL 1.0.x, 1.1.x and 3.0.x and newer, plus LibreSSL, BoringSSL, GnuTLS and NSS/NSPR.
  • The gotls module captures plaintext HTTPS/TLS communication from Go programs.
  • The gnutls and nss modules capture plaintext from GnuTLS and NSS/NSPR libraries without needing a CA certificate.
  • The mysqld module audits SQL queries on MySQL 5.6, 5.7 and 8.0 and on MariaDB, while the postgres module captures queries from PostgreSQL 10+.
  • The bash and zsh modules audit shell command history for host security monitoring.
  • The OpenSSL module offers three capture modes: pcap/pcapng to store plaintext in pcap-NG format, keylog/key to save TLS handshake keys to a file, and text to write plaintext directly.
  • Library location can be pointed at explicitly with the --libssl flag, which also accepts a program path when the target is statically linked.

Who uses it and how

  • Security auditors run sudo ecapture tls on a host and make an ordinary HTTPS request, for example curl https://google.com, to read the full HTTP/2 headers and body of traffic they would otherwise never see.
  • Android security teams use the aarch64 build for Android HTTPS capture on devices where installing a custom certificate is not an option.
  • Database administrators enable the mysqld or postgres module to audit executed SQL statements across MySQL 5.6/5.7/8.0, MariaDB and PostgreSQL 10+.
  • Host-level monitoring workflows combine the bash and zsh modules with TLS capture to correlate commands with the network traffic they trigger.
  • Operations teams run the tool in containers against live services, mounting a host path to collect captured output.

Getting started

Download the ELF binary package from the GitHub releases page, extract it, and run sudo ecapture --help; alternatively, on Linux, pull gojue/ecapture:latest from Docker Hub and run it with docker run --rm --privileged=true --net=host.

How it compares

No list of paid products this project replaces is given, and the facts name no comparable tools, so eCapture stands alone in this registry. Its distinguishing trait among the categories it touches is that it observes plaintext inside the process's crypto library instead of terminating or re-encrypting connections the way a proxy-based interception setup would.

When to use it — and when not to

A self-hoster must be prepared to grant root or specific Linux capabilities — and to accept that the documented Docker invocation uses --privileged=true, with specific capabilities recommended instead for production. It should not be picked by anyone on Windows or macOS, which are unsupported, nor by anyone unable to meet the kernel floor for their architecture. Because capture happens in kernel and library internals, it is a specialist auditing instrument rather than a general network monitor.

project readme (upstream, from github) — read inline

eCapture (旁观者)
Capture SSL/TLS plaintext with eBPF—no MITM proxy or custom CA installation.

English · 汉字
CodeQL Latest release HomePage

Star History Rank GitHub Trending Repository of the Day

[!IMPORTANT] Supports Linux and Android on x86_64 (kernel 4.18+) and aarch64 (kernel 5.5+). The kernel requirement applies per CPU architecture for both Linux and Android. Requires root privileges or specific Linux capabilities. Does not support Windows or macOS.


Introduction

  • Captures plaintext TLS/SSL traffic from OpenSSL, LibreSSL, BoringSSL, GnuTLS, and NSS/NSPR libraries.
  • Supports plaintext capture for Go TLS programs, including HTTPS/TLS traffic in Go applications.
  • Audits bash and zsh command history for host security monitoring.
  • Audits MySQL queries and supports MySQL 5.6/5.7/8.0 and MariaDB.

Getting started

Download

ELF binary file

[!TIP] Supports Linux/Android on x86_64 and aarch64.

Download the ELF binary package from the releases page, extract it, and run:

sudo ecapture --help

Docker image

[!TIP] Linux only.

# Pull the Docker image
docker pull gojue/ecapture:latest

# Run it
docker run --rm --privileged=true --net=host -v ${HOST_PATH}:${CONTAINER_PATH} gojue/ecapture ARGS

⚠️ Security note: --privileged=true grants full host access. For production use, prefer specific capabilities instead. See the Minimum Privileges Guide.

See Docker Hub for more information.

Capture OpenSSL plaintext data

sudo ecapture tls

eCapture automatically detects the system's OpenSSL library and starts capturing plaintext traffic. When you make an HTTPS request, such as curl https://google.com, the captured request and response are displayed:

...
INF module started successfully. moduleName=EBPFProbeOPENSSL
??? UUID:233851_233851_curl_5_1_172.16.71.1:51837, Name:HTTP2Request, Type:2, Length:304
header field ":method" = "GET"
header field ":path" = "/"
header field ":authority" = "google.com"
...

📄 For complete output examples, see docs/example-outputs.md.

Modules

The eCapture tool includes 8 modules that can capture plaintext data from TLS/SSL libraries such as OpenSSL, GnuTLS, NSS/NSPR, BoringSSL, and GoTLS. It also supports auditing commands and queries from Bash, MySQL, and PostgreSQL applications.

  • bash: captures bash commands
  • zsh: captures zsh commands
  • gnutls: captures plaintext from GnuTLS libraries without needing a CA certificate
  • gotls: captures plaintext communication from Go programs using TLS/HTTPS
  • mysqld: captures SQL queries from MySQL 5.6/5.7/8.0 and MariaDB
  • nss: captures plaintext from NSS/NSPR libraries without needing a CA certificate
  • postgres: captures SQL queries from PostgreSQL 10+
  • tls: captures plaintext TLS/SSL traffic without a CA certificate (supports OpenSSL 1.0.x/1.1.x/3.0.x and newer)

You can use ecapture -h to view the full list of subcommands.

OpenSSL module

eCapture searches the default library paths from /etc/ld.so.conf to locate shared libraries and detect the OpenSSL library location. You can also set the library path explicitly with the --libssl flag.

If the target program is statically linked, you can set the program path directly as the value of the --libssl flag.

The OpenSSL module supports three capture modes:

  • pcap/pcapng mode stores captured plaintext data in pcap-NG format.
  • keylog/key mode saves TLS handshake keys to a file.
  • text mode captures plaintext data directly, either writing it to a file or printing it to the console.
Pcap mode

Supports TLS-encrypted HTTP 1.0/1.1/2.0 over TCP and HTTP/3 (QUIC) over UDP.

You can specify -m pcap or -m pcapng together with --pcapfile and -i. The default value of --pcapfile is ecapture_openssl.pcapng.

sudo ecapture tls -m pcap -i eth0 --pcapfile=ecapture.pcapng tcp port 443

This command saves captured plaintext packets as a pcapng file, which can be opened with Wireshark.

📄 For complete pcapng mode output, see docs/example-outputs.md.

Keylog mode

You can specify -m keylog or -m key together with the --keylogfile option. The default output file is ecapture_masterkey.log.

The captured OpenSSL TLS master secret is saved to --keylogfile. You can also enable tcpdump capture and then open the file in Wireshark, setting the master secret path to view plaintext packets.

sudo ecapture tls -m keylog -keylogfile=openssl_keylog.log

You can also use tshark for real-time decryption and display:

tshark -o tls.keylog_file:ecapture_masterkey.log -Y http -T fields -e http.file_data -f "port 443" -i eth0
Text mode
sudo ecapture tls -m text

This outputs all plaintext data packets.

GoTLS module

Similar to the OpenSSL module.

gotls command

Capture TLS plaintext data.

Step 1:

sudo ecapture gotls --elfpath=/home/cfc4n/go_https_client --hex

Step 2:

/home/cfc4n/go_https_client
More help
sudo ecapture gotls -h

Other modules

Modules such as bash, mysqld, and postgres can also be used. You can view the full list with ecapture -h.

Videos

eCaptureQ GUI application

eCaptureQ is a cross-platform graphical client for eCapture that visualizes eBPF-based TLS capture capabilities. Built with Rust + Tauri + React, it provides a responsive, real-time interface for analyzing encrypted traffic without needing a CA certificate. It simplifies complex eBPF capture workflows and makes them easier to use.

It supports two modes:

  • Integrated mode: unified Linux/Android execution
  • Remote mode: Windows/macOS/Linux clients connect to a remote eCapture service

Event forwarding

Event forwarding projects

Video demonstration

https://github.com/user-attachments/assets/c8b7a84d-58eb-4fdb-9843-f775c97bdbfb

🔗 GitHub repository

Protobuf protocols

For details of the Protobuf log schema used by eCapture/eCaptureQ, see:

Star History

Star History Chart

Security & operations

Contributing

See CONTRIBUTING for details on submitting patches and the contribution workflow.

Compilation

Custom compilation

You can customize the features you want, such as setting the uprobe offset address to support statically linked OpenSSL libraries. Refer to the compilation guide for detailed instructions.

Remote configuration updates

After eCapture is running, you can dynamically modify configurations through HTTP interfaces. Refer to the HTTP API documentation.

Event forwarding

eCapture supports multiple event-forwarding methods. You can forward events to packet capture software such as Burp Suite. For details, refer to the Event Forwarding API documentation.

Frequently asked questions

Is ecapture free to use?

ecapture is open source under the Apache-2.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does ecapture do?

Capture SSL/TLS plaintext with eBPF—no MITM proxy or custom CA installation. Supports Linux and Android on x86_64 and arm64.

What is ecapture written in?

ecapture is primarily written in C. Its source is publicly available at https://github.com/gojue/ecapture, and it has 15,490 GitHub stars.